← Consultant · Practitioner

Knowledge material · ~6 min read

Consultant · Practitioner

You scope and deliver real projects, not just changes.

Overview

Practitioner consultants take a business outcome and produce a working system on a deadline. You write a statement of work, design for the bad day (BCDR (Business Continuity and Disaster Recovery)), administer Azure with intent, speak enough AWS (Amazon Web Services) to be dangerous, and architect identity that survives audits.

BCDR design

  • ▸RPO (Recovery Point Objective) = how much data you can lose. RTO (Recovery Time Objective) = how long you can be down.
  • ▸Map each system to RPO/RTO; cost scales inversely.
  • ▸Document failover & failback. Run a DR (Disaster Recovery) test once a year minimum.
  • ▸Tabletop exercises beat plans no one has read.

Azure administration

  • ▸Landing zones: management, identity, connectivity, workload subscriptions.
  • ▸Policy enforces guardrails (allowed regions, required tags, deny public IP (Internet Protocol)).
  • ▸Bicep / Terraform for repeatability — portal for exploration only.
  • ▸Cost Management alerts per subscription; budgets fail loud, not silent.

AWS Cloud Practitioner mindset

  • ▸Region (geo) → AZ (datacenter) → VPC (your network) → subnet.
  • ▸IAM (Identity and Access Management) = identity. Policies are JSON (JavaScript Object Notation); deny wins ties.
  • ▸EC2/S3/RDS (Remote Desktop Services)/Lambda — compute, object store, managed DB, functions.
  • ▸Shared Responsibility Model: AWS of the cloud, you in the cloud.

Identity architecture

  • ▸One identity provider (Entra) ideally; everything federates via SAML (Security Assertion Markup Language)/OIDC (OpenID Connect).
  • ▸SCIM (System for Cross-domain Identity Management) provisions and de-provisions automatically.
  • ▸PIM (Privileged Identity Management) / just-in-time for privileged roles.
  • ▸Conditional Access matrix: user risk × sign-in risk × device × app.

Glossary

RPO/RTO
Recovery Point / Time Objectives — data loss & downtime budgets.
Landing zone
Pre-built cloud account skeleton with policies and networking.
SAML/OIDC
SSO (Single Sign-On) protocols — XML-era and modern OAuth-based.
PIM
Privileged Identity Management — time-boxed admin access.

Common pitfalls

Practice drills